ePrint Report: Finding Collisions for Round-Reduced Romulus-H

Marcel Nageler, Felix Pallua, Maria Eichlseder

Romulus-H is a hash function that currently competes as a finalist in the NIST Lightweight Cryptography competition. It is based on the Hirose DBL construction which is provably secure when used with an ideal block cipher. However, in practice, ideal block ciphers can only be approximated. The security of concrete instantiations must be cryptanalyzed carefully; the security margin may be higher or lower than in the secret-key …

